Skip to content

Determine recommendations for cooldown periods #683

@dave2wave

Description

@dave2wave

This is mostly about actions, but the discussion should contemplate all dependency cycles.

We need a reasonable discussion of alternative plans (and not a filibuster via a wall of text.)

The following shows our current choice, but we should consider other timings.

infrastructure-actions project repositories
none 4 days
4 days 7 days

Goals are conflicting

  1. Upgrade versions quickly.
  2. Upgrade versions securely.

Metadata

Metadata

Assignees

Labels

criticalgatewayThings related to the GitHub Actions allowlist gateway

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions